Contents

This document provides the steps required in order to tune the
Intrusion Prevention System (IPS) for False Positive Prevention using IPS
Device Manager (IDM) or IPS Manager Express (IME). False positive tuning on IPS
is achieved by a feature called Event Action Filter (EAF).

Example: False Positive Event: Signature 1300 triggers
for traffic coming from and to known trusted hosts.

Note: This is just an example for demonstration purposes only. If you are
unsure whether a particular event due to signature trigger is benign or not,
contact Cisco Technical Support for further analysis.